Virtual asset service providers (VASPs) frequently operate as part of larger corporate groups, comprising various subsidiaries, affiliates, and parent companies. While a specific entity within such a group might directly offer virtual asset services, regulators are increasingly scrutinising the entire corporate structure to ensure comprehensive oversight.
This approach aims to prevent regulatory arbitrage, ensure financial stability across the group, and mitigate risks like money laundering and terrorist financing. Consequently, even non-operating parent companies could find themselves drawn into the regulatory net, facing new obligations under Pakistan’s evolving virtual asset framework.
Operators must therefore understand how their broader corporate structure influences their licensing requirements and ongoing compliance. Overlooking these group-level considerations could lead to significant regulatory challenges and potential enforcement actions.
What is a group structure in the context of virtual assets?
A group structure refers to a collection of legally distinct entities, such as subsidiaries, affiliates, and parent companies, that are linked by common ownership or control, often with the parent company at the apex. This framework is crucial for understanding how a single VASP might be influenced or controlled by related corporate bodies.
In Pakistan, the Securities and Exchange Commission of Pakistan (SECP) already provides definitions and oversight for corporate groups. These established principles are likely to inform how the Pakistan Virtual Assets Regulatory Authority (PVARA) views virtual asset businesses operating within complex corporate structures. It is not merely about direct ownership but also about significant influence, operational control, and shared resources that bind entities together.
Why do regulators care about group structures?
Regulators like PVARA are concerned with group structures to prevent regulatory gaps, ensure consistent risk management, and prevent illicit activities from exploiting weaknesses within a complex corporate setup. This holistic view is fundamental to effective supervision of the virtual asset sector.
The Financial Action Task Force (FATF) recommendations, which Pakistan is implementing, emphasise the importance of understanding beneficial ownership and applying group-wide Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) controls. A fragmented regulatory approach, where only the direct VASP is scrutinised, could allow risks to materialise in unregulated parts of the group, ultimately affecting the stability and integrity of the licensed VASP. Regulators need to understand the full scope of operations, control, and potential liabilities across the entire corporate family. For more on this, see our article on beneficial ownership disclosure.
When might a parent company need a VASP licence?
A parent company might need a VASP licence if it directly performs regulated virtual asset activities, exerts significant operational control over a VASP subsidiary’s regulated functions, or is deemed by PVARA to be integral to the provision of virtual asset services. This extends beyond simple equity ownership to the substance of the activities performed.
While PVARA’s proposed framework is still under consultation, international regulatory trends suggest several scenarios where a parent company could be brought into the licensing perimeter:
- Direct VASP Activities: If the parent company itself directly offers services such as exchange, custody, transfer, or participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
- Operational Control: Where the parent company dictates key operational decisions for its VASP subsidiary, including risk management frameworks, compliance policies, or the underlying technology infrastructure used for virtual asset services.
- Holding Client Assets: If the parent entity holds or controls client virtual assets, even if the direct VASP services are offered by a subsidiary.
- Revenue Generation: If the parent company directly derives significant revenue from the provision of virtual asset services, beyond simple dividends from a subsidiary.
PVARA’s interpretation of “performing virtual asset services” will likely focus on the economic reality and functional control, not solely the legal form. Operators should carefully assess who needs a VASP licence in Pakistan and who does not to avoid misinterpretations. For assistance with the application process, Sarzif Policy offers comprehensive VASP licensing services.
What are the implications for entities within a group?
All entities within a group, including parent companies, may face increased scrutiny regarding their governance, financial health, and adherence to compliance standards, even if only one entity holds the VASP licence. This extends the regulatory burden beyond the immediate operating VASP.
Key implications include:
- Consolidated Supervision: Regulators may seek to supervise the group on a consolidated basis, requiring group-wide AML/CFT policies, risk assessments, and internal controls. This ensures a consistent approach to managing risks across all relevant entities.
- Information Sharing: Expect requirements for robust information sharing across the group for compliance purposes, enabling the VASP to meet its obligations regarding customer due diligence, transaction monitoring, and suspicious activity reporting.
- Capital Requirements: While specific capital requirements primarily apply to the licensed VASP, PVARA may assess the financial strength of the parent company or require guarantees to ensure the VASP’s solvency. Understanding VASP capital requirements is crucial.
- Fit and Proper Tests: Key personnel across the group, including parent company directors and senior management, may need to pass fit and proper tests to ensure their integrity and competence. Our analysis on fit and proper tests provides further detail.
- Corporate Governance: The SECP’s existing role in corporate governance will intersect with PVARA’s virtual asset regulations, requiring clear governance structures across the group. Learn more about SECP and virtual assets.
How does PVARA approach group licensing?
PVARA’s proposed framework, drawing from FATF guidelines, indicates an intention to assess licensing applications within the context of the broader corporate group, focusing on control, risk management, and overall operational integrity. This means PVARA will likely look beyond the individual applicant.
PVARA, as Pakistan’s dedicated virtual asset regulator (learn more about what PVARA is), is expected to take a holistic view of an applicant’s business, including its parent company and other affiliates. The application process will likely demand detailed information about the entire group structure, including ownership charts, inter-company agreements, and financial relationships. While the specific details are still being finalised, operators should anticipate requirements for group-wide AML/CFT policies and risk management frameworks, even if specific operational duties are decentralised. The approach to corporate structuring for a Pakistani VASP will significantly impact these considerations. For the latest updates and proposed rules, operators should consult the official PVARA website: https://pvara.org.
What information must be disclosed about the group?
Applicants must typically disclose comprehensive details about their entire corporate group, including ownership structures, control mechanisms, financial relationships, and the identities of all beneficial owners and key management personnel. This transparency is vital for regulatory oversight.
Here is a list of common disclosures expected:
- Comprehensive Organisational Chart: A detailed diagram illustrating all entities within the group, their legal relationships, ownership percentages, and control structures.
- Beneficial Ownership Information: Full identification and verification of all ultimate beneficial owners (UBOs) across the entire corporate group, ensuring transparency about who ultimately owns or controls the VASP.
- Key Personnel Details: Information on directors, senior management, and compliance officers, not just of the applicant VASP, but also of the parent company and other relevant group entities, particularly concerning their fit and proper status.
- Financial Statements: Consolidated financial statements for the group, along with individual statements for the applicant VASP and any other significant entities.
- Inter-company Agreements: Copies of any agreements between group entities that relate to the VASP’s operations, such as shared services, technology provision, funding arrangements, or intellectual property licensing.
- Group-Level Risk Assessments: Documentation of group-wide risk assessments for AML/CFT, operational risks, and cybersecurity.
- Regulatory Status of Other Entities: Details of the regulatory status of other group entities in different jurisdictions, especially if they are also involved in virtual asset or financial services.
What are the potential challenges for group entities?
Group entities may face challenges including increased compliance costs, complex reporting requirements, potential conflicts of interest, and the need to harmonise policies and procedures across diverse business lines and jurisdictions. These complexities demand careful planning and resource allocation.
- Enhanced Compliance Burden: Extending comprehensive AML/CFT and other regulatory requirements across an entire group can be resource-intensive, requiring significant investment in personnel, technology, and training.
- Data Protection and Privacy: Managing customer data and other sensitive information across multiple entities and jurisdictions within a group poses complex data protection and privacy challenges.
- Jurisdictional Differences: Harmonising policies and procedures becomes difficult when group entities operate in diverse regulatory environments with differing legal requirements.
- Reputational Risk: A compliance failure or enforcement action in one part of the group can have severe negative reputational and financial consequences for the entire group.
- Enforcement Actions: Regulators may pursue enforcement actions not just against the licensed VASP but also against the parent company or other group entities for compliance failures within the VASP subsidiary. Understanding the cost of non-compliance is critical for groups.
- Outsourcing Oversight: If shared services subsidiaries provide critical functions, the VASP must ensure proper oversight and risk management as per outsourcing and third-party risk rules.
How can groups prepare for these regulations?
Groups should proactively map their corporate structure, identify all entities involved in or influencing virtual asset activities, conduct a group-wide risk assessment, and establish robust, harmonised compliance frameworks and governance structures. Early preparation is key to navigating the regulatory landscape successfully.
Here are practical steps for preparation:
- Conduct a Group-Wide Regulatory Mapping: Clearly identify all entities within the corporate group and assess their current and potential involvement in virtual asset activities. Determine which entities might fall within PVARA’s regulatory perimeter, directly or indirectly.
- Review Corporate Governance: Ensure clear lines of responsibility and accountability across the group, particularly for virtual asset operations. This includes defining roles for the board of directors and senior management at both the parent and subsidiary levels.
- Develop a Unified Compliance Framework: Establish a comprehensive AML/CFT framework that applies group-wide, covering policies, procedures, risk assessments, and staff training. This framework should be adaptable to specific jurisdictional requirements.
- Assess Financial and Operational Resilience: Evaluate the financial health and operational resilience of the entire group, ensuring adequate capital, liquidity, and robust IT systems to support the VASP’s activities.
- Engage with Experts: Seek advice from regulatory experts who understand Pakistan’s virtual asset framework and international best practices for group structures. This can help identify potential issues early and guide the application process.
| Entity Type | Primary Activity | Potential Licensing Impact | Key Considerations |
|---|---|---|---|
| Direct VASP Subsidiary | Offers virtual asset services to customers | Requires full VASP licence from PVARA. | Must meet all capital, governance, AML/CFT, and operational requirements. |
| Parent Holding Company | Holds equity in subsidiaries, provides group oversight | May require licence if actively involved in VASP operations or deemed to control key functions. | Scrutiny on control, financial support, group-wide policies, and beneficial ownership. |
| Shared Services Subsidiary | Provides IT, HR, or back-office support to VASP entity | Generally not licensed, but subject to outsourcing and third-party risk management rules. | Must adhere to VASP’s compliance standards; VASP remains accountable for outsourced functions. |
About this analysis
This analysis by Sarzif Policy is based on a review of publicly available consultation papers from PVARA, directives from the State Bank of Pakistan (SBP), guidelines from the Financial Action Task Force (FATF), and general principles of financial regulation as applied by bodies like the Securities and Exchange Commission of Pakistan (SECP) and the Federal Board of Revenue (FBR). While we strive for accuracy, Pakistan’s virtual asset regulatory framework is still at a consultation stage, and specific requirements are subject to change. Operators must verify all current details and obligations directly with PVARA or other relevant authorities. This article is intended for informational purposes only and does not constitute legal or regulatory advice.